ZachXBT links Humanity Protocol and Kelp DAO hacks after funds merge

ZachXBT links Humanity Protocol and Kelp DAO hacks after funds merge

On-chain traces show proceeds from the two 2026 exploits converging in shared Bitcoin wallets, reinforcing suspicion of a Lazarus Group-linked laundering pipeline and complicating recovery efforts.

BTC
ETH
BNB

Fact Check
The original ZachXBT Telegram investigation post (t.me/s/investigations/347) directly contains a 'Humanity Protocol & Kelp DAO Exploit Link' section stating the funds from both exploits commingled, suggesting the same attacker. Three independent crypto news outlets (PANews, BlockBeats, Odaily) corroborate this with consistent details (Kelp DAO ~$292M April 18 2026, Humanity Protocol ~$32-36M June 9 2026), and the news reports add that new evidence rules out an insider attack. CoinDesk confirms the Humanity Protocol exploit was caused by a compromised developer laptop. All key claim elements—the merged/commingled funds, the link to overlapping attackers, the two 2026 exploits, and the ruling out of an insider attack—are supported by the primary and secondary sources.
Summary

Stolen funds from the Humanity Protocol and Kelp DAO attacks have converged in shared wallets after the Humanity attacker moved 15,403 ETH, worth about $23.6 million, to a new Ethereum address and then bridged the funds onto Bitcoin, where they mixed with proceeds tied to the April Kelp DAO exploit. ZachXBT and blockchain analyst Specter said the flow is consistent with a single laundering pipeline often associated with the Lazarus Group. The Kelp DAO attack on April 18 was previously tied by Chainalysis to a compromise of internal RPC nodes operated by LayerZero Labs alongside a DDoS attack on external nodes, allowing 116,500 rsETH to be released without a corresponding burn on the source chain. Arbitrum’s Security Council froze more than 30,000 ETH of downstream funds, while KelpDAO’s emergency pause blocked another $95 million from being drained. Humanity Protocol’s June breach followed a different intrusion path but was also linked to North Korea-linked actors in post-mortem findings. Quantstamp said a company director, Chong Yee Wai, was phished through an email impersonating Bithumb, giving the attacker remote access to a Windows machine and access to MetaMask keys. The attacker then minted and sold unauthorized $H tokens on Ethereum and BNB Smart Chain, sending the token down roughly 89%. Quantstamp said known attacker addresses held more than $21 million in ETH. The overlap in stolen-fund flows adds to evidence that the two incidents may be connected and may also intensify legal disputes over frozen assets. Plaintiffs seeking to enforce more than $877 million in unpaid U.S. judgments against North Korea have already targeted about 30,766 ETH frozen after the Kelp DAO exploit, while Arbitrum governance had been pursuing a separate recovery plan backed by Aave Labs, KelpDAO, LayerZero, EtherFi and Compound.

Terms & Concepts
  • RPC nodes: Servers that let applications communicate with a blockchain and submit or read transactions.
  • DDoS attack: A disruption attempt that floods targeted systems with traffic to overwhelm or disable them.
  • Lazarus Group: A hacking group widely linked to North Korea and often accused of major crypto thefts.